Daily Podcast full article
Microsoft Patches Record 974 Flaws, Including Two Windows Zero-Days
Microsoft’s September 2026 Patch Tuesday has become a scale event: 974 vulnerabilities across Windows, Office, SQL Server and other products, two of them already exploited in the wild, forcing security teams to choose speed, sequencing and business continuity all at once.

A Patch Tuesday measured in operational capacity
Microsoft’s September 2026 security release landed as the largest Patch Tuesday batch yet, with reporting based on Microsoft’s own update data putting the total at 974 vulnerabilities across its software portfolio . The release includes two Windows zero-days that Microsoft says were already exploited before patches were available: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows Advanced Local Procedure Call, or ALPC .
The headline number matters, but the operational meaning matters more. A release of this size is not simply a bigger checklist for endpoint teams. It is a stress test of enterprise patch governance: asset visibility, ring-based deployment, exception handling, change windows, rollback planning and the ability to identify which systems are exposed to which classes of flaw.
Security teams now face a familiar but sharper dilemma. The exploited zero-days demand fast action, yet a nearly thousand-CVE release cannot be pushed blindly into production estates that include domain controllers, database clusters, Exchange servers, Remote Desktop infrastructure, Office clients and line-of-business applications. Patch velocity has become an infrastructure metric, not just a security metric.
The two exploited Windows bugs come first
The two active-exploitation flaws are both elevation-of-privilege vulnerabilities, meaning an attacker generally needs some prior foothold before using them to gain stronger control over a compromised system. That does not make them secondary. In real intrusions, local privilege escalation is often the step that turns a phished workstation, abused account or initial malware implant into SYSTEM-level access, credential theft, lateral movement and persistence.
CVE-2026-81963 affects the Windows Update Stack and is described as an improper link-resolution issue before file access; Tenable’s analysis says successful exploitation could let an attacker elevate to SYSTEM privileges . Tenable also noted that, among Windows Update Stack elevation-of-privilege vulnerabilities patched since 2022, this is the first to be exploited in the wild as a zero-day .
CVE-2026-85880 affects Windows ALPC and is a heap-based buffer overflow, also rated important with a CVSSv3 score of 7.8 in Tenable’s summary . SecurityWeek reported that the ALPC bug could allow a local attacker to gain System privileges, and that exploitation can occur without additional user interaction once code is already executing in a low-privilege AppContainer context .
CISA added both CVE-2026-81963 and CVE-2026-85880 to its Known Exploited Vulnerabilities catalog on September 8, 2026, citing evidence of active exploitation . That KEV listing turns Microsoft’s “exploited” tag into an operational escalation for U.S. federal civilian agencies and a strong prioritization signal for private-sector teams.
Why the totals differ, and why 974 is still the story
Several security vendors reported slightly different totals for September’s Microsoft release. The Hacker News and SecurityWeek reported 974 Microsoft vulnerabilities . CrowdStrike counted 972 vulnerabilities in Microsoft’s September security update release . BleepingComputer counted 966 flaws because it excludes vulnerabilities released earlier in the month from its Patch Tuesday tally . Tenable described 964 CVEs, with 104 critical and 860 important .
These differences are not unusual in a release that folds together Microsoft CVEs, already-resolved cloud issues, Chromium-related items, external CVEs and month-to-date disclosures. For defenders, the discrepancy is less important than the shared conclusion: every reputable tally points to a record or near-record Patch Tuesday event, and every analysis identifies the same two exploited Windows vulnerabilities as immediate priorities.
The product spread also explains the triage problem. The Hacker News reported 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL and 22 in Developer Tools, with more than 110 shortcomings rated critical . SecurityWeek’s breakdown similarly identified Windows as the largest category and listed additional fixes across Office, SQL, Developer Tools, SharePoint Server, Azure, Skype for Business and Exchange Server .
The backlog behind the zero-days
The exploited bugs should be handled first, but they are not the only material risks in the release. CrowdStrike’s analysis said elevation-of-privilege issues led the month with 437 patches, followed by 258 remote-code-execution patches and 171 information-disclosure patches . BleepingComputer’s category breakdown was close: 438 elevation-of-privilege vulnerabilities, 258 remote-code-execution vulnerabilities and 173 information-disclosure vulnerabilities .
That distribution matters because enterprise attackers do not need every vulnerability. They need one reliable entry point, one privilege step and one path to persistence or data access. The large number of elevation bugs gives defenders a long tail of post-compromise hardening work; the large number of RCE bugs raises the question of which server-side services are reachable from untrusted networks.
The Zero Day Initiative highlighted 20 patches it considered potentially “wormable,” meaning remote, unauthenticated code execution without user interaction on affected systems . Its list included vulnerabilities in Windows DHCP Server, Active Directory Domain Services, Windows Message Queuing, RRAS, NFS, DNS Server, SMB Client, IP Helper, Netlogon, Internet Connection Sharing, SSTP and Failover Cluster components . Even if some are difficult to exploit in practice, that many theoretically self-spreading candidates in a single cycle should change how enterprises stage testing.
Exchange, SharePoint and SQL also require special attention. ZDI singled out CVE-2026-55007, a Microsoft Exchange Server remote-code-execution vulnerability, as especially important because an unauthenticated remote attacker could trigger code execution through mail processing of a malicious Visio attachment, without relying on Preview Pane behavior . It also advised rapid testing and deployment for internet-facing SharePoint servers and warned that SQL Server patching would not be trivial this month .
A practical order of operations
The first step is to separate emergency action from full-cycle remediation. Systems affected by CVE-2026-81963 and CVE-2026-85880 should move into the fastest safe deployment track, especially laptops, VDI pools, administrator workstations, jump hosts and servers where local privilege escalation would give attackers access to high-value credentials. The CISA KEV addition makes those two CVEs the clearest “do now” items .
The second step is to identify exposed server roles. Internet-facing Exchange, SharePoint, Remote Desktop, DNS, DHCP, VPN-adjacent and remote-management infrastructure should be reviewed against the RCE and wormable candidate lists before less exposed desktop-only issues. ZDI’s warning about 20 unauthenticated, no-user-interaction RCE candidates is the kind of signal that should override simple CVSS-only prioritization .
The third step is to use rings aggressively. Pilot updates on representative Windows client builds, server roles and Office configurations; then expand to high-risk assets before broad desktop deployment. With this many CVEs, the goal is not perfect simultaneity. It is to close known exploitation paths quickly while preventing an avoidable outage that forces rollback across the estate.
The fourth step is to document exceptions as risk decisions, not as ticket residue. If a SQL cluster, Exchange node or legacy Windows Server instance cannot be patched immediately, security teams should record the reason, compensating controls, exposure status, owner and a dated remediation plan. The September release is too large for informal deferrals.
The larger lesson: patching is now throughput engineering
This release shows how vulnerability discovery, including AI-assisted analysis cited by several researchers, is outpacing the old monthly patch rhythm . That may be good news in the long run if flaws are found and fixed before attackers independently exploit them. In the short run, however, enterprises must absorb the operational shock.
The answer is not to patch everything with equal urgency. It is to build systems that can patch exploited vulnerabilities quickly, test critical business workloads continuously and rank the remaining backlog by exploitability, exposure and business criticality. September’s 974-flaw Microsoft release is therefore not just a security bulletin. It is a measurement of whether an organization’s patch pipeline has enough threads.
Sources from the last 72 hours
- [1]Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-DaysSep 9, 2026, 12:00 AM UTC
- [2]Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days - SecurityWeekSep 8, 2026, 7:20 PM UTC
- [3]Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-daysSep 8, 2026, 6:18 PM UTC
- [4]September 2026 Patch Tuesday: Updates and Analysis | CrowdStrikeSep 8, 2026, 12:00 AM UTC
- [5]September 2026 Microsoft Patch Tuesday | Tenable®Sep 8, 2026, 6:30 PM UTC
- [6]Zero Day Initiative — The September 2026 Security Update ReviewSep 8, 2026, 12:00 AM UTC
- [7]CISA Adds Four Known Exploited Vulnerabilities to Catalog | CISASep 8, 2026, 12:00 AM UTC
AI-generated article based on recent web research, then preserved as a dated editorial snapshot.

Comments
Be the first to comment.